Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-29227 PoC — Sourcecodester Car Rental Management System 输入验证错误漏洞

Source
Associated Vulnerability
Title:Sourcecodester Car Rental Management System 输入验证错误漏洞 (CVE-2020-29227)
Description:Sourcecodester Car Rental Management System是美国Sourcecodester公司的一个汽车租赁管理系统。 SourceCodester Car Rental Management System 1.0版本存在安全漏洞,该漏洞源于未经身份验证的用户可以使用“page”参数中的部分文件名对index.php文件执行文件包含攻击,以导致执行代码时包含本地文件。
Description
Car Rental Management System 1.0 allows an unauthenticated user to perform a file inclusion attack against the /index.php file with a partial filename in the "page" parameter, leading to code execution.
File Snapshot

id: CVE-2020-29227 info: name: Car Rental Management System 1.0 - Local File Inclusion author: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.